Poland Faces EU Procedure Over Supervision of Data Processing in Justice System

FINANCEPoland Faces EU Procedure Over Supervision of Data Processing in Justice System
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

The European Commission has initiated an infringement procedure against Poland over the lack of provisions ensuring proper supervision of personal data processing in the area of public order protection and the justice system. The case has been registered under number INFR(2026)2130.

The problem had long been flagged by the Personal Data Protection Office. Mirosław Wróblewski, President of the Polish Data Protection Authority, repeatedly pointed out that Polish regulations do not ensure full compliance with the EU’s so-called Law Enforcement Directive, namely Directive 2016/680. Several months ago, he sent formal letters on this matter to the Ministers of the Interior and Justice, drawing attention to the urgent need to adapt national regulations.

What Is an Infringement Procedure?

An infringement procedure is a mechanism used by the European Commission when it considers that a Member State is failing to fulfil its obligations under European Union law. The aim of the procedure is to remove violations and ensure that national legislation complies with EU regulations.

The first stage is a formal notice calling on the Member State to remedy the infringement. In it, the Commission indicates the nature of the breach of EU law and expects explanations within a specified deadline. If the response is deemed insufficient, the Commission may issue a so-called reasoned opinion, in which it formally presents its objections and sets a deadline for adapting the legislation.

The next step may be to refer the case to the Court of Justice of the European Union. If the CJEU confirms the infringement and the state still fails to bring its law into compliance, the Commission may bring another action, this time seeking the imposition of financial penalties.

The Polish Data Protection Authority Had Long Warned About the Law Enforcement Directive

The Polish Data Protection Authority’s concerns relate primarily to the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime. In the supervisory authority’s view, the Act in its current form does not provide full guarantees for the rights of people whose data is processed.

The Law Enforcement Directive regulates the processing of personal data by competent authorities for purposes related, among other things, to the prevention, detection, investigation and prosecution of criminal offences and the execution of penalties. Its purpose is to ensure a balance between the effectiveness of state authorities and the protection of citizens’ fundamental rights.

However, Mirosław Wróblewski has pointed out that the Polish Act contains numerous exclusions, which mean that it does not cover all areas of data processing provided for in the Directive. This problem was already raised at the stage of issuing opinions on the draft implementing act, as well as during evaluations of the Directive’s operation in 2021 and 2025.

Data in Case Files Outside Real Protection

One of the most important problems identified by the Polish Data Protection Authority concerns personal data processed during procedural activities and included in case files. In the authority’s assessment, such data is subject neither to the Act implementing the Law Enforcement Directive nor to the general principles of personal data protection, but only to the provisions of criminal procedure.

This, in turn, means a lack of full guarantees for the individuals concerned. These include, among others, the right to information, access to data, rectification, erasure, restriction of processing, the right to lodge a complaint with an independent supervisory authority and the right to an effective judicial remedy.

According to the Polish Data Protection Authority, the current model may lead to a situation in which individuals whose data is contained in case files are not guaranteed the standard of protection required under European Union law.

Problems With Supervision Over Courts and Prosecutor’s Offices

Another issue raised by the President of the Polish Data Protection Authority concerns supervision over the processing of personal data by courts in the exercise of judicial functions. Under EU rules, such supervision should be organised in a way that guarantees judicial independence, but at the same time it should be real, transparent and effective.

The authority points out that Polish provisions in this area need clarification. There is also a lack of uniform interpretative guidelines, which leads to discrepancies in practice. Courts of appeal more often adopt a broad understanding of exclusions from the application of the Directive, while regional and district courts sometimes apply a narrower interpretation.

As a result, the supervisory system is inconsistent and legal certainty is weakened. Although organisational provisions assign courts certain tasks and powers of a supervisory authority, many competent authorities do not identify the areas in which they should apply the Act of 14 December 2018.

Even more serious doubts concern the prosecutor’s office. The Polish Data Protection Authority stresses that, under the Constitution, the prosecutor’s office does not administer justice in the strict sense. Consequently, there are no grounds for covering it with the exclusions provided for courts under the Law Enforcement Directive.

In the opinion of the President of the Polish Data Protection Authority, the processing of data by the prosecutor’s office should be subject to full, independent supervision. In practice, however, supervision is hierarchical and cascading in nature, which, given the structure of the prosecutor’s office, raises questions about the actual independence of supervisory bodies.

Lack of Effective Sanctions and Problems With the Role of the Data Protection Officer

The Polish Data Protection Authority also draws attention to the lack of appropriate sanctions for violations of the provisions implementing the Law Enforcement Directive. Article 57 of Directive 2016/680 obliges Member States to adopt effective, proportionate and dissuasive sanctions and ensure that they are applied.

However, the Polish Act does not equip the President of the Polish Data Protection Authority with instruments enabling the application of such sanctions. In the authority’s view, this is one of the significant gaps in the current system.

Another problem concerns the role of the data protection officer. The authority points out that the applicable regulations incorrectly define the tasks of the DPO and imprecisely regulate obligations related to notifications concerning data protection officers.

Concerns also relate to the exclusion of the application of the Act of 14 December 2018 to certain tasks performed by services listed in its provisions. According to the Polish Data Protection Authority, many regulations, although formally repeating the wording of the Directive, are formulated so generally that in practice they do not ensure effective protection of fundamental rights.

Consequences for EU Information Systems

Incorrect implementation of the Law Enforcement Directive may also have implications for the functioning of large-scale European Union information systems in Poland. This concerns, among other things, supervision over access by public order authorities to personal data processed in these systems.

The absence of clear and effective supervisory provisions may make it more difficult to ensure a uniform standard of data protection and the proper performance of obligations arising from EU law.

The Commission Confirms the Importance of the Problem

The European Commission’s decision to launch an infringement procedure confirms that the concerns raised by the Polish Data Protection Authority were not merely interpretative in nature. They concern real doubts as to whether Polish regulations comply with European Union law.

At the same time, the launch of the procedure does not yet prejudge its final outcome. It is part of a broader process of monitoring whether Member States correctly implement EU law.

The Polish Data Protection Authority hopes that the Commission’s actions will contribute to the swift adoption of legislative changes ensuring full compliance of Polish regulations with European Union law. The authority also declares its readiness to cooperate with the relevant institutions in adapting national regulations and presenting recommendations based on its experience to date.

Check out our other content
Related Articles
The Latest Articles